Learn
Learning Hub
Short, structured explanations of the ideas every tool assumes, plus practice environments and reference material — clearly separated into CyberAtlas content and external destinations.
Suggested first hour
- 1 · Read what a port is and what an IP address is not.
- 2 · Open the Nmap entry and read the first three commands — do not run anything yet.
- 3 · Pick the Absolute Beginner path and set up its stage-one lab.
Concepts
One question per page, written to be finished in a few minutes and re-read later with more context.
- Beginner7 min
What is an IP address?
An IP address identifies an interface on a network so packets can be delivered to the right place. It is not a person, not a building and not a permanent label for a machine.
Read concept - Beginner6 min
What is a port?
A port is a 16-bit delivery number that lets one IP address host many services. It says 'hand this to that listener', nothing more.
Read concept - Beginner9 min
What is DNS?
DNS is a global, cached, hierarchical lookup system. Most 'the site is down' and 'why does this IP appear?' investigations come back to it.
Read concept - Beginner10 min
What is HTTP?
HTTP is a text protocol of requests and responses. Understanding the four parts of a request explains proxies, cookies, caching, and half of all web findings.
Read concept - Beginner8 min
TCP vs UDP
TCP negotiates and confirms a stream. UDP sends datagrams and accepts silence. Nearly every 'is this port open?' ambiguity comes from that difference.
Read concept - Beginner6 min
What is CIDR?
CIDR notation writes an address plus a prefix length to describe a block: /24 is 256 addresses, /16 is 65,536. Reading it quickly is a practical scanning and scoping skill.
Read concept - Beginner8 min
Hashing vs encryption
Hashing is one-way fingerprinting; encryption is reversible with a key. Mixing them up causes designs that leak, and reports that overstate or understate risk.
Read concept - Beginner7 min
What is a vulnerability?
A vulnerability is a reachable weakness that enables a specific harm. Missing any of those three parts and you have a configuration observation, not a finding.
Read concept - Beginner6 min
What is a firewall?
A firewall decides which flows may exist based on header fields. It is not an antivirus, an input validator, or a reason to trust anything that arrives on an allowed port.
Read concept - Beginner7 min
What is OSINT?
Open-source intelligence is the disciplined collection, evaluation and reporting of publicly available information. The discipline is the whole point.
Read concept
Practice labs
Isolated targets you own or are given access to. · 6 external destinations
- Practice labBeginnerOWASP
OWASP Juice Shop
Deliberately vulnerable single-page web app with an integrated scoring server. Runs in Docker or Node on your own machine.
Open external resource - Practice labBeginnerCommunity
DVWA — Damn Vulnerable Web Application
Small PHP/MySQL app with selectable difficulty, useful for watching how a fix changes behaviour.
Open external resource - Practice labIntermediateRapid7
Metasploitable 3
Deliberately vulnerable VM image for network and host assessments in an isolated range.
Open external resource - Practice labBeginnerOverTheWire
OverTheWire: Bandit
Wargame levels that teach SSH, permissions, pipes and grep by requiring them. The most common first stop before anything graphical.
Open external resource - Practice labIntermediateCyberDefenders
CyberDefenders
Blue-team labs built on real memory, packet and disk images with question-driven analysis.
Open external resource - Practice labIntermediateCyberDefenders
Blue Team Labs Online
Investigation challenges with evidence downloads; a natural companion to the forensics category.
Open external resource
CTF resources
Competitions and archives, ranked by beginner-friendliness. · 4 external destinations
- CTFBeginnerTryHackMe
TryHackMe guided rooms
Hand-held paths with in-browser VMs; useful when you want structure rather than a blank target.
Open external resource - CTFIntermediateHack The Box
Hack The Box
Labs and competitive machines with write-ups gated behind the same access model as the ranges.
Open external resource - CTFBeginnerCarnegie Mellon University
picoCTF
Long-running high-school CTF with a persistent practice archive — good for reverse engineering and forensics firsts.
Open external resource - CTFIntermediateCommunity
CTFtime
Calendar and results index for CTFs. Use it to find an upcoming event rather than an archive.
Open external resource
Certifications
What each exam actually measures, without the marketing. · 4 external destinations
- CertificationBeginnerCompTIA
CompTIA Security+
Vendor-neutral baseline across vocabulary, controls and domains. Widely used as an HR keyword rather than a competence proof.
Open external resourceIssued by CompTIA
- CertificationBeginnerINE
eJPT
Practical junior pentest exam in an assigned lab range; a common first hands-on certification.
Open external resourceIssued by INE
- CertificationAdvancedOffSec
OSCP
24-hour practical exam against multiple lab machines with a report. Read the current exam description before preparing — it changes.
Open external resourceIssued by OffSec
- CertificationAdvancedSANS/GIAC
GIAC incident-handling certifications
Defensive, incident-oriented credentials with substantial training cost attached; typically employer-funded.
Open external resourceIssued by GIAC
Books
Reference material that outlives tool versions. · 2 external destinations
- BookIntermediateWiley
The Web Application Hacker's Handbook (2e)
Older than current framework defaults but still the clearest taxonomy of testing techniques and reasoning.
Open external resource - BookIntermediateNo Starch Press
Practical Malware Analysis
Structured lab discipline for static and dynamic analysis; the exercises assume an isolated VM.
Open external resource
Frameworks & references
Authoritative documents worth reading directly. · 4 external destinations
- Framework / referenceMITRE
MITRE ATT&CK
Knowledge base of adversary tactics and techniques, used for detection mapping and coverage discussion.
Open external resource - Framework / referenceOWASP
OWASP Top 10
A awareness document of recurring web risk categories — useful vocabulary, not a testing methodology or a standard.
Open external resource - Framework / referenceNIST
NIST Cybersecurity Framework 2.0
Organisational functions (Govern, Identify, Protect, Detect, Respond, Recover) for structuring a programme.
Open external resource - Framework / referenceRFC Editor
RFC Editor index
When a tutorial contradicts the protocol, read the protocol. HTTP, TCP, DNS and IP are all short reads at this point.
Open external resource
Courses
Structured study with public materials. · 1 external destinations
- CourseAdvancedUMD
University of Maryland — CMSC 656 (open notes)
Publicly posted course notes on network and systems security fundamentals; a rigorous free alternative to paid intros.
Open external resource
Reading is not the whole path
Concepts and labs are inputs. A roadmap sequences them, and the tool pages carry the commands you will actually need.
Absolute Beginner
Complete newcomers, students, developers moving into security
8 stagesOSINT Investigator
Analysts, journalists, defenders, anyone doing public-record research
6 stagesWeb Pentester
Developers moving into appsec, junior testers, bug bounty newcomers
8 stages27 tools and their commands sit behind every stage listed above.